Privacy Law Blog
Knowledge Centre

5 Key Lessons from the LifeLabs Data Breach Case

February 24, 2025

When a cybersecurity breach hits, it’s like a domino effect. Suddenly, everyone’s involved – lawyers, internal personnel, outside experts, you name it. A responding organization or public body will usually take steps to investigate, whether it be as a matter of internal business procedure, compliance with statutory obligations, seeking or obtaining legal advice, or preparation for anticipated litigation.

Often these purposes overlap, which raises the question: what information in the investigation file is privileged? This key question was recently addressed in the case of LifeLabs LP v. Information and Privacy Commr. (Ontario), 2024 ONSC 2194.

By way of background, LifeLabs provides laboratory testing across Canada. In 2019, LifeLabs experienced a data breach. The data breach resulted because a software patch had not been installed. Cyber-attackers gained access to LifeLabs systems and during that year gained the personal health data of millions of Canadians. The cyber-attackers then demanded payment for the return of the data. LifeLabs paid and in exchange the cyber-attackers agreed not to release the data on the internet.

The LifeLabs data breach primarily affected Ontario and British Columbia residents, prompting investigations by both provinces’ Information and Privacy Commissioners (IPC). LifeLabs claimed privilege over requested documents, but the Court upheld the IPCs decision to reject these claims, ruling that statutory obligations override privilege for facts related to privacy breaches, and that health information custodians cannot evade their responsibilities by placing breach-related facts in privileged documents.

The LifeLabs data breach case offers valuable insights for organizations handling sensitive personal data. Here are some key takeaways from this significant incident:

1. Strengthen Cybersecurity and Limit Data Collection: Organizations must implement robust security measures, including regular audits and strong encryption. Adopting a data minimization approach by collecting only necessary information can reduce breach impacts and risk exposure.

2. Develop Comprehensive Incident Response Plans: Create well-documented, regularly tested plans with clear procedures for breach detection, containment, and notification. Define roles and responsibilities, including when to engage external support. Conduct regular drills to ensure readiness.

3. Understand Legal Privilege Limitations: Recognize that statutory obligations can override legal privilege claims, especially for facts related to privacy breaches. Be prepared to disclose factual information about breaches, even if contained in privileged documents.

4. Balance Legal and Regulatory Compliance: Work closely with legal counsel to develop strategies that fulfill obligations while protecting legitimate privileges.

5. Foster a Security-Minded Culture and Ensure Transparency: Promote ongoing security education and awareness among employees. In the event of a breach, prioritize transparent communication with affected individuals, providing clear information about risks and protective measures to maintain trust and mitigate reputational damage.

By learning from these lessons, organizations can better protect sensitive data, prepare for potential breaches, and navigate the complex legal and regulatory landscape that follows such incidents. For more information about this and other privacy related matters, get in touch with the author, Jaeda Lee, or any other member of our Privacy and Data Protection Group.

Expertise

Important Notice: The information contained in this Article is intended for general information purposes only and does not create a lawyer-client relationship. It is not intended as legal advice from Harper Grey LLP or the individual author(s), nor intended as a substitute for legal advice on any specific subject matter. Detailed legal counsel should be sought prior to undertaking any legal matter. The information contained in this Article is current to the last update and may change. Last Update: February 24 2025.

Related

Ryan Bencic quoted in <em>Business in Vancouver</em> 
Ryan Bencic quoted in <em>Business in Vancouver</em>  Ryan Bencic quoted in Business in Vancouver 
Harper Grey supports Althra second cohort launch event
Harper Grey supports Althra second cohort launch event
Natasha Cooke reappointed to Insurance Law Section Executive of Canadian Bar Association
Natasha Cooke reappointed to Insurance Law Section Executive of Canadian Bar Association Natasha Cooke reappointed to Insurance Law Section Executive of Canadian Bar Association
April Wilkinson elected to Elder Law section of Canadian Bar Association
April Wilkinson elected to Elder Law section of Canadian Bar Association April Wilkinson elected to Elder Law section of Canadian Bar Association
Jennifer Camara attends webinar for the Estate Planning Counsel of Canada
Jennifer Camara attends webinar for the Estate Planning Counsel of Canada Jennifer Camara attends webinar for the Estate Planning Counsel of Canada
Berta Lopera elected to Elder Law section of Canadian Bar Association
Berta Lopera elected to Elder Law section of Canadian Bar Association Berta Lopera elected to Elder Law section of Canadian Bar Association
Adam Way and Nicola Virk present at BEST 2026 Conference
Adam Way and Nicola Virk present at BEST 2026 Conference Adam Way and Nicola Virk present at BEST 2026 Conference Adam Way and Nicola Virk present at BEST 2026 Conference
Harper Grey lawyers attend the Canadian Bar Association Bench and Bar Dinner
Harper Grey lawyers attend the Canadian Bar Association Bench and Bar Dinner
April Wilkinson, Berta Lopera, and Jasmine Kang attend The Great Canadian Bucket List Travel Event
April Wilkinson, Berta Lopera, and Jasmine Kang attend The Great Canadian Bucket List Travel Event
Harper Grey Hosts 2026 Spring Insurance Law Seminar
Harper Grey Hosts 2026 Spring Insurance Law Seminar
Rebecca Dales and Jasmine Kang attend the First Canadian Title Speaker Series
Rebecca Dales and Jasmine Kang attend the First Canadian Title Speaker Series Rebecca Dales and Jasmine Kang attend the First Canadian Title Speaker Series Rebecca Dales and Jasmine Kang attend the First Canadian Title Speaker Series
Prentice Durbin participates in Corporate and M&A Panel at TAG Alliances Spring International Conference
Prentice Durbin participates in Corporate and M&A Panel at TAG Alliances Spring International Conference Prentice Durbin participates in Corporate and M&A Panel at TAG Alliances Spring International Conference
Intestate Inheritance of a Family Home, the Court’s Interpretation of s. 33 of <em>WESA</em>
Intestate Inheritance of a Family Home, the Court’s Interpretation of s. 33 of WESA
Harper Grey Hosts Ask Us Anything Employer Webinar: Family Status Discrimination – A Deep Dive into a Real Case
Harper Grey Hosts Ask Us Anything Employer Webinar: Family Status Discrimination – A Deep Dive into a Real Case
April Wilkinson and Jasmine Kang attend Association of Women in Finances’ 2026 PEAK Awards Gala
April Wilkinson and Jasmine Kang attend Association of Women in Finances’ 2026 PEAK Awards Gala April Wilkinson and Jasmine Kang attend Association of Women in Finances’ 2026 PEAK Awards Gala April Wilkinson and Jasmine Kang attend Association of Women in Finances’ 2026 PEAK Awards Gala
arrow icon

Subscribe